For anyone got by this, note that the law in most countries requires the bank to return any funds lost through such an attack.
It would fall in the same category as 'bank believed the customer instructed them to transfer funds when the customer did not make such an instruction'.
The customer in this case is the actual human account holder - not the customers computer system or account.
Notably, this is why lots of tech support scams try to trick the customer into transferring money, even though the scammer already has full access to the victims bank login details and browser. The scammers know that if they just make the transfer themselves, it is the bank they are defrauding, and the bank will typically try far harder to shut them down.